NA - CVE-2025-0423 - In the "bestinformed Web" application, some...
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is...
NA - CVE-2025-0424 - In the "bestinformed Web" application, some...
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple authenticated stored cross-site scripting vulnerabilities. An authenticated attacker is...
NA - CVE-2025-0425 - Via the GUI of the "bestinformed Infoclient", a...
Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which this client connects. This is dangerous as...
Medium - CVE-2025-0864 - The Active Products Tables for WooCommerce. Use...
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcodes_set' parameter in all...
Critical - CVE-2024-12860 - The CarSpot – Dealership Wordpress Classified...
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the...
Medium - CVE-2024-13316 - The Scratch & Win – Giveaways and Contests....
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to unauthorized access due to a missing...
Medium - CVE-2024-13395 - The Threepress plugin for WordPress is...
The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due to...
Medium - CVE-2024-13718 - The Flexible Wishlist for WooCommerce –...
The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is...
Medium - CVE-2024-13369 - The Tour Master - Tour Booking, Travel, Hotel...
The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to...
NA - CVE-2025-0981 - A vulnerability exists in ChurchCRM 5.13.0 and...
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor...